2026 CVE Vulnerabilities
43,277 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59214 | CRITICAL | 9 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs c... |
| CVE-2026-58459 | CRITICAL | 9.6 | 1.8% | Jul 9, 2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows ... |
| CVE-2026-51599 | CRITICAL | 9.8 | 0.2% | Jul 9, 2026 | An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n al... |
| CVE-2026-51597 | CRITICAL | 9.1 | 0.2% | Jul 9, 2026 | MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authenticat... |
| CVE-2026-13461 | CRITICAL | 9.6 | 0.2% | Jul 9, 2026 | When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 ... |
| CVE-2026-42486 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23562 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23561 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23560 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23559 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-23556 | CRITICAL | 9.4 | — | Jul 9, 2026 | When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ... |
| CVE-2026-14261 | CRITICAL | 9.1 | — | Jul 9, 2026 | A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation ... |
| CVE-2026-12116 | CRITICAL | 9.8 | — | Jul 9, 2026 | A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,... |
| CVE-2026-56291 | CRITICAL | 9.8 | 8.6% | Jul 9, 2026 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension B... |
| CVE-2026-5955 | CRITICAL | 9.8 | 0.4% | Jul 9, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software an... |
| CVE-2026-2342 | CRITICAL | 9.3 | 0.4% | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Inform... |
| CVE-2026-15158 | CRITICAL | 9.8 | 1.0% | Jul 9, 2026 | The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, ... |
| CVE-2026-14245 | CRITICAL | 9.8 | 0.6% | Jul 9, 2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2026-47840 | CRITICAL | 9.3 | 0.1% | Jul 9, 2026 | A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate fro... |
| CVE-2026-47826 | CRITICAL | 9.1 | 0.3% | Jul 9, 2026 | The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfi... |
| CVE-2026-54782 | CRITICAL | 10 | 0.2% | Jul 8, 2026 | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, ... |
| CVE-2026-15113 | CRITICAL | 9.6 | 0.2% | Jul 8, 2026 | Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially ... |
| CVE-2026-55471 | CRITICAL | 9.1 | 0.3% | Jul 8, 2026 | HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10... |
| CVE-2026-52200 | CRITICAL | 9.8 | 0.2% | Jul 8, 2026 | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax... |
| CVE-2026-44024 | CRITICAL | 9.8 | 1.1% | Jul 8, 2026 | Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now